LOPDP
Organic Law on Protection of Personal Data
Ecuador’s Organic Law on Protection of Personal Data (Ley Orgánica de Protección de Datos Personales or LOPDP) establishes the country’s framework for protecting personal data and regulating its processing by public and private organisations.
The LOPDP was enacted in 2021 and is supplemented by the General Regulation to the LOPDP, issued through Executive Decree No. 904 and published on 13 November 2023. The regulatory framework establishes requirements covering consent, data subject rights, security, international transfers, accountability, and other aspects of personal data processing.
Ecuador’s LOPDP requires organisations to identify an appropriate lawful basis before processing personal data. Where consent is used, it must be free, specific, informed, and unequivocal. Certain categories of sensitive personal data are subject to enhanced requirements.
The framework also gives individuals rights over their personal data and establishes obligations relating to security, transparency, international transfers, data protection impact assessments, and compliance governance.
Ecuador
Enacted in 2021
The LOPDP was enacted in 2021, with its implementing General Regulation issued in 2023. Ecuador’s data protection framework is currently administered and supervised by the Superintendencia de Protección de Datos Personales (SPDP).
Ameerikad
Who must comply with the LOPDP?
The LOPDP and its Regulation apply to natural and legal persons, public and private entities, and organisations that process personal data within the scope of Ecuador’s framework.
The General Regulation expressly covers national and foreign controllers and processors where their processing activities fall within the applicable territorial scope. It can also apply to organisations processing the personal data of non-residents when the relevant processing takes place in Ecuador.
Organisations should therefore assess:
- Where their processing takes place
- Where the relevant individuals are located
- Whether they act as a controller or processor
- Whether they offer goods or services involving individuals in Ecuador
- Whether they monitor or otherwise process personal data within Ecuador
- Whether an Ecuadorian representative is required
Penalties under the LOPDP
The LOPDP establishes administrative sanctions for violations of Ecuador’s personal data protection framework.
Penalties vary according to the type and seriousness of the infringement and, for certain organisations, can be calculated by reference to income or turnover.
The applicable sanction depends on the specific violation, the organisation involved, and the circumstances established by the competent authority.
Organisations should therefore treat privacy compliance as an ongoing governance obligation rather than relying only on a privacy policy or consent banner.
Key obligations under the LOPDP
Organisations processing personal data in Ecuador should:
- Identify an appropriate lawful basis for each processing purpose.
- Obtain valid consent where consent is the applicable legal basis.
- Ensure consent is free, specific, informed, and unequivocal.
- Apply additional requirements when processing sensitive personal data.
- Provide transparent information about processing activities.
- Respect data subject rights.
- Implement appropriate technical and organisational security measures.
- Maintain appropriate documentation and evidence of compliance.
- Conduct data protection impact assessments where required.
- Manage international transfers in accordance with applicable requirements.
- Notify qualifying personal data security incidents.
- Appoint a Data Protection Officer where required.
- Maintain appropriate procedures for responding to data subject requests.
Lawful basis and consent requirements
Consent is one of the lawful bases available under Ecuador’s LOPDP.
Where consent is used, it must be:
- Free
- Specific
- Informed
- Unequivocal
The LOPDP defines consent as a manifestation of free, specific, informed, and unequivocal will through which the data subject authorises the controller to process their personal data.
However, organisations should not assume that consent is required for every processing activity.
The LOPDP recognises multiple lawful bases for processing personal data. Organisations should therefore determine the appropriate legal basis for each processing purpose before implementing their consent strategy.
For websites, this distinction is particularly important when managing analytics, advertising, personalisation, and other tracking technologies.
Sensitive personal data
The LOPDP provides enhanced protection for special categories of personal data.
Organisations processing sensitive information should assess the applicable legal basis and additional requirements before processing begins.
Consent mechanisms should clearly identify relevant sensitive data processing where consent is required and should not bundle sensitive-data consent into unclear or overly broad permissions.
Data subject rights
The LOPDP provides individuals with rights concerning their personal data.
These include:
Right of access
Individuals can request information about their personal data and relevant processing activities.
Right of rectification and updating
Individuals can request correction or updating of inaccurate, incomplete, or outdated personal data.
Right of deletion
Individuals may request deletion of their personal data where the applicable legal requirements are satisfied.
Right of opposition
Individuals can object to certain processing activities where the conditions established by the law apply.
Right to portability
Under applicable conditions, individuals may request their personal data in a structured format and exercise their right to data portability.
Other rights
The LOPDP also provides additional rights and protections, including rights relating to automated decision-making and the processing of personal data.
Organisations should maintain a documented process for receiving, authenticating, tracking, and responding to these requests.
Privacy notices and transparency
Organisations should provide individuals with clear and understandable information about how their personal data is processed.
A privacy notice should explain relevant information such as:
- Identity of the controller
- Categories of personal data collected
- Purposes of processing
- Applicable legal basis
- Recipients or categories of recipients
- International transfers, where applicable
- Data retention information
- Data subject rights
- How individuals can exercise their rights
- Contact information for privacy-related requests
Transparency should be maintained throughout the data lifecycle and not limited to the initial collection stage.
Data security
The LOPDP requires controllers and processors to implement appropriate security measures for protecting personal data.
The law specifically requires security measures to take into account factors such as the nature of the personal data, the processing context, risks, threats, and vulnerabilities.
Security measures can include:
- Technical safeguards
- Organisational controls
- Access management
- Encryption where appropriate
- Monitoring
- Data minimisation
- Incident response
- Business continuity measures
- Employee awareness and training
Organisations should periodically assess whether their safeguards remain appropriate as processing activities and risks change.
Data protection impact assessments
The Ecuadorian framework includes data protection impact assessments (DPIAs) for processing activities that may create significant risks to individuals.
A DPIA can help organisations identify:
- The nature and purpose of processing
- Potential risks to individuals
- Security and privacy controls
- Necessity and proportionality of processing
- Measures for reducing identified risks
Organisations carrying out high-risk processing should assess whether a DPIA is required before processing begins.
Data Protection Officer
The Ecuadorian framework establishes requirements concerning the appointment of a Data Protection Officer (DPO) for certain organisations and processing activities.
The DPO function can include responsibilities such as:
- Advising on data protection obligations
- Monitoring compliance
- Supporting DPIAs
- Cooperating with the supervisory authority
- Providing guidance on data subject rights
- Promoting privacy governance within the organisation
Organisations should assess whether their size, activities, data categories, or processing operations trigger a DPO requirement.
Data breach notification
The LOPDP framework establishes obligations relating to personal data security breaches.
Organisations should maintain procedures to:
- Detect security incidents.
- Assess whether personal data is affected.
- Document the incident.
- Determine applicable notification requirements.
- Notify the competent authority where required.
- Communicate with affected individuals where applicable.
- Implement corrective measures.
A privacy programme should therefore connect security incident management with data protection compliance.
International data transfers
Ecuador’s framework regulates the transfer and communication of personal data, including international transfers.
The SPDP issued specific 2025 regulations addressing national and international transfers or communications of personal data. The rules require organisations to apply the relevant provisions of the LOPDP and its General Regulation when conducting international data transfers.
Organisations should assess:
- Where personal data is being transferred
- Who receives the data
- The purpose of the transfer
- The categories of data involved
- The destination country
- Applicable safeguards
- Contractual requirements
- The legal basis for the transfer
International data flows should be documented as part of the organisation’s broader data mapping programme.
Data retention and deletion
Personal data should not be retained indefinitely without an appropriate purpose.
Organisations should establish retention periods based on:
- Purpose of processing
- Applicable legal obligations
- Contractual requirements
- Security considerations
- Data subject rights
- Regulatory requirements
When personal data is no longer required, organisations should apply appropriate deletion, anonymisation, or other legally required measures.
Ecuador’s SPDP has also issued a specific regulation concerning the anonymisation, blocking, suspension, and elimination of personal data, further developing this aspect of the framework.
Cookies and online tracking
Cookies, pixels, advertising trackers, analytics tools, and other technologies can involve the processing of personal data.
Organisations operating websites in Ecuador should therefore identify:
- Cookies and trackers deployed
- Data collected by each technology
- Processing purposes
- Third-party recipients
- International transfers
- Applicable lawful bases
- Whether consent is required
- Whether trackers should be blocked before consent
Where consent is the applicable lawful basis, ConsentX can help organisations obtain valid consent before applicable tracking technologies are activated.
How ConsentX helps with LOPDP compliance
ConsentX helps organisations operationalise key privacy and consent requirements across websites and digital experiences.
Free, specific and informed consent
Create consent experiences designed to capture the characteristics required when consent is the applicable legal basis.
Purpose-based consent
Clearly explain the purposes associated with cookies, trackers, analytics, advertising, and other processing activities.
Sensitive-data consent
Support separate handling of sensitive categories where enhanced consent or other legal requirements apply.
Cookie and tracker management
Scan websites to identify cookies and trackers and prevent applicable non-essential technologies from activating before consent.
Consent receipts
Maintain auditable records of users’ consent choices and relevant contextual information.
Data subject request management
Support workflows for access, rectification, deletion, opposition, portability, and other applicable privacy requests.
Regional compliance
Use ConsentX’s region rule engine to configure consent experiences according to the applicable jurisdiction.
Get LOPDP ready with ConsentX
Scan your website → Identify trackers → Map purposes → Configure consent → Block applicable trackers → Record consent → Manage privacy requests
Build a more transparent and auditable privacy experience for users in Ecuador.
Kuidas täita LOPDP nõudeid ConsentX-iga
- 1
Scan your website
Scan your website to identify cookies, trackers, pixels, scripts, and third-party technologies.
- 2
Map processing purposes
Identify why each technology processes personal data and determine the appropriate lawful basis.
- 3
Configure an Ecuador-ready consent banner
Where consent is the applicable legal basis, configure a banner that provides clear information and captures free, specific, informed, and unequivocal consent.
- 4
Block applicable trackers before consent
Prevent applicable non-essential cookies and trackers from activating until the required consent has been obtained.
- 5
Record consent evidence
Maintain consent receipts containing relevant information about the user’s choice and the consent event.
- 6
Manage data subject requests
Centralise requests for access, rectification, deletion, opposition, portability, and other applicable rights.
- 7
Monitor your website
Regularly rescan your website to detect new trackers, scripts, vendors, or changes in processing activities.
Korduma kippuvad küsimused
Country under LOPDP
Legal disclaimer
This page provides a plain-English summary of Ecuador’s personal data protection framework for general informational purposes and is not legal advice. Organisations should assess their specific processing activities and consult qualified Ecuadorian legal counsel where necessary.